CVE-2019-5736
90Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 98%
from disclosure to weapon1 days
Published on NVDFeb 11
1st PoC+1d
metasploitJan 1
VulnCheck+1291d
exploitation probability
98%top 1% of all CVEs
observed exploitation
yesVulnCheck
50 public exploit(s)
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Affected products
n/a · n/apublic PoCs found — 50
exploitdbwww.exploit-db.com/exploits/46359unverifiedexploitdbwww.exploit-db.com/exploits/46369unverifiedgithubgithub.com/Frichetten/CVE-2019-5736-PoC★ 659githubgithub.com/q3k/cve-2019-5736-poc★ 210githubgithub.com/twistlock/RunC-CVE-2019-5736★ 86githubgithub.com/jas502n/CVE-2019-5736★ 14githubgithub.com/agppp/cve-2019-5736-poc★ 7githubgithub.com/epsteina16/Docker-Escape-Miner★ 3githubgithub.com/GiverOfGifts/CVE-2019-5736-Custom-Runtime★ 1githubgithub.com/likekabin/CVE-2019-5736★ 1githubgithub.com/b3d3c/poc-cve-2019-5736★ 1githubgithub.com/panzouh/Docker-Runc-Exploit★ 1githubgithub.com/milloni/cve-2019-5736-exp★ 1githubgithub.com/Perimora/cve_2019-5736-PoC★ 0githubgithub.com/sastraadiwiguna-purpleeliteteaming/Holistic-Deconstruction-of-CVE-2019-5736-★ 0githubgithub.com/Billith/CVE-2019-5736-PoC★ 0githubgithub.com/yyqs2008/CVE-2019-5736-PoC-2★ 0githubgithub.com/stillan00b/CVE-2019-5736★ 0githubgithub.com/RyanNgWH/CVE-2019-5736-POC★ 0githubgithub.com/Lee-SungYoung/cve-2019-5736-study★ 0githubgithub.com/h-wookie/cve-2019-5736-poc★ 0githubgithub.com/geropl/CVE-2019-5736★ 0githubgithub.com/BBRathnayaka/POC-CVE-2019-5736★ 0githubgithub.com/h3x0v3rl0rd/CVE-2019-5736★ 0githubgithub.com/fahmifj/Docker-breakout-runc★ 0githubgithub.com/takumak/cve-2019-5736-reproducer★ 0githubgithub.com/si1ent-le/CVE-2019-5736★ 0githubgithub.com/sonyavalo/CVE-2019-5736-Dockerattack-and-security-mechanism★ 0githubgithub.com/likekabin/cve-2019-5736-poc★ 0githubgithub.com/shen54/IT19172088★ 0cve_referencepacketstormsecurity.com/files/165197/Docker-runc-Command-Execution-Proof-Of-Concept.htmlunverifiedcve_referencepacketstormsecurity.com/files/163339/Docker-Container-Escape.htmlunverifiedvulncheckvulncheck.com/xdb/4463e53f5834unverifiedvulncheckvulncheck.com/xdb/bb174ce4f36cunverifiedvulncheckvulncheck.com/xdb/c317b3d456ddunverifiedvulncheckvulncheck.com/xdb/f12a3e511eadunverifiedvulncheckvulncheck.com/xdb/855a012ee5b4unverifiedvulncheckvulncheck.com/xdb/c05359a63da0unverifiedvulncheckvulncheck.com/xdb/fc8679cdf2e2unverifiedvulncheckvulncheck.com/xdb/4bc294031050unverifiedvulncheckvulncheck.com/xdb/a668e29fca88unverifiedvulncheckvulncheck.com/xdb/dbfbe09bd96bunverifiedvulncheckvulncheck.com/xdb/fbad66534b9bunverifiedvulncheckvulncheck.com/xdb/c37072317e5dunverifiedvulncheckvulncheck.com/xdb/dfb45d4148e6unverifiedvulncheckvulncheck.com/xdb/8b94a95c6eeaunverifiedvulncheckvulncheck.com/xdb/34a990f00e33unverifiedvulncheckvulncheck.com/xdb/f9fb9c2111f2unverifiedcve_referencewww.exploit-db.com/exploits/46369/unverifiedcve_referencewww.exploit-db.com/exploits/46359/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00074.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00091.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00029.htmlhttp://packetstormsecurity.com/files/163339/Docker-Container-Escape.htmlhttp://packetstormsecurity.com/files/165197/Docker-runc-Command-Execution-Proof-Of-Concept.html